INNER CODE UNIT · Python

executable_basename

magicsword-io/LOLRMM · bin/generate_detections.py:17

def executable_basename(path):
    """Read an installation path, not a command line, on any host OS.

    Preserve Sigma wildcards within filenames, but exclude directory patterns,
    invalid Windows placeholder names, and arguments following an executable.
    """
    if not isinstance(path, str):
        return None
    path = path.strip()
    if len(path) >= 2 and path[0] == path[-1] and path[0] in "\"'":
        path = path[1:-1]
    if any(char in path for char in '"|') or re.search(r"\.exe\s", path, re.I):
        return None
    name = ntpath.basename(path)
    if (
        not name
        or name.startswith("*")
        or not name.lower().endswith(".exe")

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…